EU AI Act Transparency Rules Now Enforceable
The European Commission's AI Act transparency rules became fully enforceable on August 2, 2026. Providers and deployers must now disclose AI interactions and label synthetic content, aiming to combat deception in the public information space.

Since August 2, 2026, providers and deployers of certain AI systems in the European Union have faced new obligations to disclose AI interactions and label synthetic content. The European Commission states these rules are intended to reduce deception and strengthen the integrity of Europe's information environment, according to a report from Tech Policy Press.
Several regulatory developments are now in effect. Article 50's transparency rules require providers to inform people when they interact directly with an AI system. Providers of systems that generate or manipulate synthetic content must ensure outputs are marked in a machine-readable format where required. Deployers have separate obligations concerning the disclosure of deepfakes and AI-generated text on matters of public interest.
These obligations come with exceptions. They include law enforcement use, minor editorial assistance, artistic or satirical works, and content that has undergone human review with clear editorial responsibility.
New Enforcement Powers
Second, the AI Office gained full enforcement powers over general-purpose AI (GPAI) providers. Although GPAI obligations had applied since August 2025, full enforcement by the Commission did not start until August 2. Third, Article 4’s AI-literacy requirement, in force since February 2025, entered a new phase of supervision. This provision requires providers and deployers to ensure a sufficient level of AI literacy among their staff.
Potential for Democratic Resilience
The report argues that for democratic resilience, three aspects of this implementation deserve attention: transparency, accountability, and institutional readiness.
The new rules aim to strengthen transparency by preventing citizens from being deceived by synthetic media. They require machine-readable marking of AI-generated content, mandatory disclosure of AI interaction, and documentation from GPAI providers. The goal is to preserve institutional trust. Citizens who stop believing what they see may disengage from democratic participation.
However, recent implementations highlight limits. Honoring its commitment under the EU's Code of Practice on Transparency, Anthropic started embedding an invisible watermark in text generated by Claude models released after August 2. Anthropic noted that the absence of a watermark doesn't guarantee content wasn't AI-generated. A screenshot, format conversion, or simple file re-save can break the chain of provenance.
Article 50 therefore targets a single point in the chain, but democratic resilience depends on what endures through several such points.
The new rules also enable accountability. The GPAI provisions require providers to document training content, adopt copyright-compliant practices, and maintain risk-management records. This creates the documentation necessary for enforcement.
Third, the rules contribute to institutional readiness. Article 4's literacy obligation pushes public bodies, campaigns, and newsrooms to achieve a baseline competence in spotting AI-generated content. Transparency and accountability fail without this readiness.
Loopholes and Limits
While the AI Act introduces regulatory guardrails, loopholes remain that will likely limit its effectiveness in safeguarding democracy.
Much disinformation targeting European democracies originates from foreign states like Russia and China, which are beyond the AI Act's jurisdiction. Its impact is indirect, constraining the commercial platforms and tools used by foreign actors. Whether this indirect pressure actually limits state-backed operations remains an open question.
The Act also has almost no practical reach over a malicious actor running a modified, open-weight model on private infrastructure. Such an actor can generate harmful content entirely outside any provider's oversight.
A related problem is laundering. A bad actor can upload an illegal deepfake first on an unmonitored app like Telegram, where copying strips any hidden tracking data. By the time the fake reaches major platforms, detection becomes more challenging, and Article 50's watermarking requirement offers little protection.
Mandatory labeling can also create an unintended defense. Bad actors can dismiss genuine footage simply by claiming it lacks a watermark or looks altered. This could turn a tool built to expose fakes into one that helps deny reality.
Finally, the newly enforceable provisions do not address deeper societal problems like political polarization and declining institutional trust. The AI Act regulates how AI content is generated, but says nothing about why people are inclined to believe fakes.
Complementary Tools
Given these limits, strengthening democratic resilience further requires tools beyond the AI Act. The Digital Services Act (DSA) is the most obvious complement. Where the AI Act addresses content generation, the DSA targets the algorithms that amplify it, and can force major platforms to detect and restrict viral fake media.
The mechanism works when it has teeth. Once ChatGPT crossed the 45-million EU user threshold, the Commission classified it as a Very Large Online Search Engine, subjecting it to the DSA’s strictest rules. But the DSA has its own limits. Telegram has reported staying just below that threshold for over two years despite EU scrutiny, allowing it to evade heightened obligations.





